Privacy policy
What personal information Emitt collects, why, where it's kept, and your choices. Last updated 30 September 2026.
Draft under review. It describes how we work today and may be reworded before it's final.
Who this covers
Emitt [legal entity and ABN to be confirmed] ("we") makes emissions reporting software for Australian businesses. This policy covers:
- Visitors to emitt.com.au.
- Users of the Emitt app at app.emitt.com.au: people our customers invite to their organisation.
- Enquirers: people who email us, book a walkthrough, join our waitlist, or ask to be contacted through Microsoft Marketplace.
Questions about this policy go to [email protected].
What we collect
When you use the app: your name, work email address and role, and the organisation you belong to. We also keep an identifier from Microsoft Entra ID that links your sign-in to your account. You sign in with your work Microsoft account, so we never see or store your password. Changes you make are recorded (what changed, who changed it and when). This audit log is part of the product: it is how our customers show where their figures came from.
Data our customers put into Emitt: energy and fuel bills, meter readings, site details and addresses, and supplier and waste records. These records are about a business's operations, but they can include personal information, such as a contact name on a bill. We process them on our customer's behalf, only to provide the service to that customer.
When you visit our website: product analytics (pages visited and buttons clicked) through PostHog, on emitt.com.au only. We don't build profiles of anonymous visitors. Fonts load from Google Fonts, which receives your IP address. Our cookie notice lists what is stored in your browser.
When you contact us: the details you give us, such as your name, email, company, phone and message. They reach us by email, through our waitlist form (Loops), through our booking page (Cal.com), or from Microsoft when you select Contact me on our Microsoft Marketplace listing.
Technical information: service logs and performance data, such as request timings and errors, so we can run and secure the service. The product events we record do not contain names, email addresses or the contents of customer records.
How we use it
- To provide the app: sign-in, access control, calculations and reports.
- To keep the service secure, investigate problems and keep the audit log our customers rely on.
- To reply to enquiries and arrange walkthroughs.
- To understand how the website and product are used, so we can improve them.
We do not sell personal information, and we do not use customer data to train AI models.
Optional features
These use other services. They are off unless an administrator switches them on for their organisation, and some are not yet available to every customer.
- Energy retailer connections use Fiskil, an accredited data recipient under the Consumer Data Right, to fetch electricity usage with the account holder's consent.
- Address search finds an entity's address with Mapbox, which receives the search text.
- AI pre-fill of bills sends a document you upload to Anthropic's API, which proposes the values for a record for you to review. The document is sent for that one read, and we keep it only as the evidence you uploaded.
- The assistant answers questions about your organisation's data. Each question, with the records it needs to answer it, is sent to Anthropic's API. Emitt doesn't store the text of questions or answers.
Where it's stored
The Emitt app runs on Microsoft Azure. Customer data, including the database, uploaded files and backups, is stored in the Australia East region. The app's web pages (its code and styles, not your data) are delivered from Azure hosting outside Australia.
Some of the services we use are based overseas, mainly in the United States, and may receive personal information. Our subprocessors page lists each one, what it receives and where:
- Microsoft: Entra ID sign-in, and Azure Monitor for service logs.
- Cloudflare: website hosting and email routing.
- PostHog (website analytics), Loops (waitlist email), Cal.com (bookings) and Google (fonts).
- Anthropic (AI pre-fill and the assistant) and Mapbox (address search), only where those features are switched on.
How we protect it
Data is encrypted in transit and at rest. Each customer's data is kept separate from every other customer's, and automated tests check that separation. Application secrets are held in Azure Key Vault. People sign in through Microsoft Entra ID, and an administrator in each organisation decides who is invited. There's more on our security page.
How long we keep it
- Customer data, including users and the audit log, for as long as the customer's subscription runs. When it ends, the customer has 30 days to export it; we then delete it within a further 30 days, and backup copies expire within 14 days after that.
- A removed user's name and email stay in their organisation's audit log, because it records who made each change.
- Enquiries, waitlist sign-ups and Marketplace leads for up to 2 years after our last contact.
- Service logs for up to 90 days.
You can ask us at any time to delete personal information we hold about you. We'll tell you what, if anything, we must keep and why.
Your choices
You can ask for a copy of the personal information we hold about you, or ask us to correct it, by emailing [email protected]. If you use Emitt through your employer, some requests go through your organisation's administrator, who controls the account. We'll respond within 30 days.
Complaints
Email [email protected] first, and we'll respond within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
We'll update this page when our practices change, and change the date at the top.